← All certifications

CompTIA PenTest+

CompTIA

An intermediate-to-advanced certification validating the skills to plan, scope, and perform penetration tests and vulnerability assessments and report the results.

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 7 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

212Cyber Defense Forensics AnalystAnalyzes digital evidence and investigates computer security incidents to derive useful information in support of system/network vulnerability mitigation.Advanced511Cyber Defense AnalystUses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs.) to analyze events that occur within their environments for the purposes of mitigating threats.Intermediate521Cyber Defense Infrastructure Support SpecialistTests, implements, deploys, maintains, and administers the infrastructure hardware and software.Intermediate531Cyber Defense Incident ResponderInvestigates, analyzes, and responds to cyber incidents within the network environment or enclave.Intermediate541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Intermediate612Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).Intermediate671System Testing and Evaluation (T&E) SpecialistPlans, prepares, and executes tests of systems to evaluate results against specifications and requirements as well as analyze/report test results.Intermediate
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle60CEU per cycle

$150 CE fee per three-year renewal cycle (not billed annually; paid only when renewing via CEU upload, by the certification's expiration date).

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

PT0-003 (V3) is the current version; it launched 2024-12-17 and the prior PT0-002 retired 2025-06-17. CompTIA's page shows retirement is typically ~3 years after launch (estimated 2027) but no firm retirement date is published. CompTIA provides no holder-independent public certification lookup. Third-party verification relies on a Credly badge URL the holder chooses to share; CompTIA's own verification form requires holder-supplied identifiers/consent.

Source: CompTIA PenTest+ certification page · dated 2026-07-17 · checked 2026-07-17

Verifying it

CompTIA has no public lookup a third party can use on their own — verification depends on a badge URL you share.

A badge URL the holder shares.

PT0-003 (V3) is the current version; it launched 2024-12-17 and the prior PT0-002 retired 2025-06-17. CompTIA's page shows retirement is typically ~3 years after launch (estimated 2027) but no firm retirement date is published. CompTIA provides no holder-independent public certification lookup. Third-party verification relies on a Credly badge URL the holder chooses to share; CompTIA's own verification form requires holder-supplied identifiers/consent.

Source: CompTIA PenTest+ certification page · dated 2026-07-17 · checked 2026-07-17

Exam blueprint

Verified against CompTIA’s published outline.

PT0-003 · V3

Current

Max 90 questions · 165 minutes · passing score 750 (scale 100-900)

Engagement Management13%
Reconnaissance and Enumeration21%
Vulnerability Discovery and Analysis17%
Attacks and Exploits35%
Post-exploitation and Lateral Movement14%

PT0-003 (V3) is the current version; it launched 2024-12-17 and the prior PT0-002 retired 2025-06-17. CompTIA's page shows retirement is typically ~3 years after launch (estimated 2027) but no firm retirement date is published. CompTIA provides no holder-independent public certification lookup. Third-party verification relies on a Credly badge URL the holder chooses to share; CompTIA's own verification form requires holder-supplied identifiers/consent.

Source: CompTIA PenTest+ certification page · dated 2026-07-17 · checked 2026-07-17